Denial of Service Vulnerability in Malwarebytes Premium Driver File
CVE-2018-5271

7.8HIGH

Key Information:

Vendor
CVE Published:
8 January 2018

What is CVE-2018-5271?

In Malwarebytes Premium version 3.3.1.2183, a vulnerability exists within the driver file FARFLT.SYS that could result in a denial of service. This occurs due to insufficient validation of input values from an IOCtl command (0x9c40e008), which may lead local users to trigger a Blue Screen of Death (BSOD) or create other unspecified impacts. Despite these concerns, the vendor has reported challenges in reproducing this issue across various Windows operating systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.